
CVE-2026-48909-Joomla-SP-Exploit
CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

CVE-2026-48909 - Unauthenticated PHP Object Injection to RCE exploit for Joomla SP LMS extension versions <= 4.1.3. Exploits lmsOrders cookie…

Python exploit script for CVE-2025-66034 targeting Variatype on Hackthebox, providing initial access via command injection and base64-encoded reverse…

Proof-of-concept exploit for CVE-2023-3824 (PHP phar deserialization) enabling remote code execution via crafted phar archive and reverse shell…

Interactive Ruby shell for authorized CVE-2025-55182 (react2shell) testing

CVE-2015-6967 PoC Exploit

Armor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode injection

ASPX web shell with COFF loader for executing Beacon Object Files (BOFs) on target servers via a semi-interactive Python client, designed for…

C++ memshell DLL generator for CVE-2019-18935, enabling in-memory web shell deployment via Telerik UI deserialization with Assembly.Load and IJW…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

C# POC for CVE-2021-26855 aka ProxyLogon, supports the classically semi-interactive web shell as well as shellcode in…

Carga de archivos sin restricciones en la funcionalidad de carga de archivos grandes en `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` en…

A simple tool to interact with web shells and command injection vulnerabilities

WordPress Processing Projects Plugin <= 1.0.2 is vulnerable to Arbitrary File Upload

Exploit for CVE-2019-16278 targeting Nostromo Web Server 1.9.6, achieving remote code execution via directory traversal. Uses pwntools to deliver a…

SSH-based reverse shell management tool with native SCP/SFTP support, multiple transport protocols, Windows DLL generation, and fileless execution…

Apache Tomcat Manager API WAR Shell Upload

A collection of exploits, shellcode, and tools related to CVE-2022-24702